VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202604-4026 CVE-2026-5363 TP-LINK Technologies of Archer C7  Cryptographic Strength Vulnerability in Firmware CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation.  The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.   An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration.   This issue affects Archer C7: through Build 20220715. RSA-1024 It is encrypted using and sent to the router. Archer C7 of 2022 Year 7 Moon 15 This will affect the daily build.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-2629 CVE-2026-39813 fortinet's FortiSandbox Past traversal vulnerability in CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>. Fortinet FortiSandbox version of 5.0.0 from 5.0.5 ,and 4.4.0 from 4.4.8 in '../filedir' A path traversal vulnerability exists. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-3550 CVE-2026-39812 fortinet's FortiSandbox Cross-site scripting vulnerabilities in multiple products, including CVSS V2: -
CVSS V3: 4.8
Severity: MEDIUM
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>. This vulnerability allows an attacker to... insert attack vector here It may be possible to execute malicious code or commands through this.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability may affect other software
VAR-202604-3993 CVE-2026-39808 fortinet's FortiSandbox In OS  Command injection vulnerability CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-3329 CVE-2026-27316 fortinet's FortiSandbox Vulnerabilities related to insufficient protection of authentication information in multiple products, including CVSS V2: -
CVSS V3: 2.7
Severity: LOW
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection. This vulnerability allows authenticated administrators to perform client-side checks. LDAP It is possible to read the server's authentication information.There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-3534 CVE-2026-25691 fortinet's FortiSandbox Path traversal vulnerabilities in multiple products, including CVSS V2: -
CVSS V3: 6.7
Severity: MEDIUM
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. In addition, all of the information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-2837 CVE-2025-61886 fortinet's FortiSandbox Cross-site scripting vulnerabilities in multiple products, including CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests. [CWE-79] There is a vulnerability that allows an attacker to craft a specially made attack. HTTP via request XSS It may be possible to carry out the attack.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-4209 CVE-2024-23104 fortinet's FortiNDR Information leakage vulnerabilities in multiple products, including CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only permission on system maintenance to access backup information via crafted HTTP requests. During system maintenance, a remotely authenticated attacker with at least read-only privileges could potentially access it. HTTP It may be possible to access backup information via a request.There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-1847 CVE-2026-31924 Apache Software Foundation of APISIX Vulnerability in plaintext transmission of important information in CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-1987 CVE-2026-31923 Apache Software Foundation of APISIX Vulnerability in plaintext transmission of important information in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .All information handled by the software may be leaked to the outside. In addition, information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability will not affect other software
VAR-202604-1913 CVE-2026-31908 Apache Software Foundation of APISIX Vulnerability in sanitizing special elements in CVSS V2: -
CVSS V3: 9.1
Severity: CRITICAL
Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-1914 CVE-2025-40745 Siemens' Simcenter 3d Vulnerabilities related to certificate validation in multiple products, including CVSS V2: -
CVSS V3: 3.7
Severity: Medium
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks. Man-in-the-Middle They may carry out an attack.- Some of the information handled by the software may be leaked to external parties. - No rewriting will occur to the information handled by the software. - The software will not stop
VAR-202604-2239 CVE-2026-6024 Shenzhen Tenda Technology Co.,Ltd. of i6  Path traversal vulnerability in firmware CVSS V2: 7.5
CVSS V3: 7.3
Severity: Medium
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-2498 CVE-2026-6016 Shenzhen Tenda Technology Co.,Ltd. of AC9  Multiple vulnerabilities in firmware CVSS V2: 9.0
CVSS V3: 8.8
Severity: High
A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The attack code is publicly available and could be exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-3433 CVE-2026-6015 Shenzhen Tenda Technology Co.,Ltd. of AC9  Multiple vulnerabilities in firmware CVSS V2: 9.0
CVSS V3: 8.8
Severity: High
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. An exploit is publicly available and can be exploited in the wild.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-1660 CVE-2026-35063 OpenPLC Project of OpenPLC_v3  Lack of Authentication Vulnerability in Firmware CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator access. role=admin You can create a new account to gain full administrator access.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-1661 CVE-2026-35556 OpenPLC Project of OpenPLC_v3  Vulnerability regarding plaintext storage of authentication information in firmware CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information. In addition, information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability will not affect other software
VAR-202604-1659 CVE-2026-28205 OpenPLC Project of OpenPLC_v3  Vulnerability in firmware where resources are initialized to insecure default values CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-2496 CVE-2026-5962 Shenzhen Tenda Technology Co.,Ltd. of ch22  Path traversal vulnerability in firmware CVSS V2: 7.5
CVSS V3: 7.3
Severity: Medium
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The exploit has already been exposed and is at risk of being misused.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
VAR-202604-3227 CVE-2026-5849 Shenzhen Tenda Technology Co.,Ltd. of I12  Path traversal vulnerability in firmware CVSS V2: 7.5
CVSS V3: 7.3
Severity: Medium
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This exploit is public and could be exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software